HomeSecurityAttacks on airlines linked to hacker from Nigeria

Attacks on airlines linked to Nigerian hacker

Security researchers have uncovered a major hacking campaign targeting airlines. It all started with the analysis of a trojan by Microsoft.

On May 11, the Microsoft Security Intelligence posted a thread on Twitter describing a campaign targeting the “aerospace and travel sectors with phishing emails containing a loader, which then installed RevengeRAT or AsyncRAT.”

See also: Safe Links: Microsoft Teams' new anti-phishing protection

hacking airlines

The operator of this campaign used email spoofing to make the emails appear to come from legitimate organizations. The emails contained a .PDF file with an embedded link, which contained a malicious VBScript. This then installed Trojan payloads on the target machine.

According to Microsoft, the malware was used to spy on victims as well as steal data (credentials, screenshots, clipboard and webcam data).

Microsoft's security team has been monitoring the hacking campaign , and now, Cisco Talos has presented its own findings on the attacks on airlines.

Cisco Talos researchers Tiago Pereira and Vitor Venturapublished a paper on Thursday detailing the attack, “Operation Layover,” which appears to be linked to an attacker who has been active since at least 2013 and has been targeting airlines for at least two years.

See also: Phishing: Still the "easy way" for ransomware attacks

This particular attacker is also linked to attacks in other sectors.

Regarding aviation targets, the samples of malicious emails the researchers found were similar to those received by Microsoft. The emails and .PDF attachments were aviation-related, with references to flight schedules, private jets, charters, cargo details, and more.

Attacks on airlines linked to Nigerian hacker
Attacks on airlines linked to Nigerian hacker

Based on passive DNS telemetry, the team believes the attacker is located in Nigeria.

The criminal started out using the off-the-shelf CyberGate malware. CyberGate was replaced with AsyncRAT in the most recent attacks.

RevengeRAT and AsyncRAT, however, are not the only malware used by the Nigerian attacker to attack airlines .A domain identified by the research team also shows that the operator is using a variant of njRAT in cyberattacks.

See also: Phishing: Without training, one in three falls victim to an attack

“Criminals who carry out smaller attacks can continue to do so for a long time without being noticed,” says Cisco Talos. However, according to the researchers, their activities can create problems for other large organizations. These are the criminals who feed the underground market with credentials and data that can be used by larger groups for activities such as big game hunting.

Source: ZDNet

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS